linux 如何查看谁在尝试登录我的 root 用户?
比如我想查看是否有人在暴力破解我的服务器,
然后我想查看这个人的 ip 地址,再然后把他加入屏蔽列表。
- 我想要知道谁在尝试登录我的root用户,而不是用last看谁最近登录了。(都登录了,我一个小白就只能选择重装系统了)
- 如何屏蔽这些人?不准再让他们试着登录了。
---2022-5-23更新---
有个家伙一直在尝试登录我的服务器,
而fail2ban好像没有效果?
☁ fail2ban tail -n 30 /var/log/fail2ban.log
2022-05-23 15:16:20,679 fail2ban.filter [1539779]: INFO [sshd] Found 164.92.114.201 - 2022-05-23 15:16:20
2022-05-23 15:16:24,986 fail2ban.filter [1539779]: INFO [sshd] Found 164.92.114.201 - 2022-05-23 15:16:24
2022-05-23 15:16:27,850 fail2ban.filter [1539779]: INFO [sshd] Found 164.92.114.201 - 2022-05-23 15:16:27
2022-05-23 15:16:30,450 fail2ban.filter [1539779]: INFO [sshd] Found 164.92.114.201 - 2022-05-23 15:16:30
2022-05-23 15:16:33,155 fail2ban.filter [1539779]: INFO [sshd] Found 164.92.114.201 - 2022-05-23 15:16:32
2022-05-23 15:16:33,955 fail2ban.actions [1539779]: WARNING [sshd] 164.92.114.201 already banned
2022-05-23 15:16:34,143 fail2ban.filter [1539779]: INFO [sshd] Found 164.92.114.201 - 2022-05-23 15:16:34
2022-05-23 15:16:37,003 fail2ban.filter [1539779]: INFO [sshd] Found 164.92.114.201 - 2022-05-23 15:16:36
2022-05-23 15:16:39,307 fail2ban.filter [1539779]: INFO [sshd] Found 164.92.114.201 - 2022-05-23 15:16:39
2022-05-23 15:16:41,204 fail2ban.filter [1539779]: INFO [sshd] Found 164.92.114.201 - 2022-05-23 15:16:41
2022-05-23 15:16:46,339 fail2ban.filter [1539779]: INFO [sshd] Found 164.92.114.201 - 2022-05-23 15:16:46
2022-05-23 15:16:46,575 fail2ban.actions [1539779]: WARNING [sshd] 164.92.114.201 already banned
2022-05-23 15:16:49,160 fail2ban.filter [1539779]: INFO [sshd] Found 164.92.114.201 - 2022-05-23 15:16:48
2022-05-23 15:16:52,366 fail2ban.filter [1539779]: INFO [sshd] Found 164.92.114.201 - 2022-05-23 15:16:52
2022-05-23 15:16:55,070 fail2ban.filter [1539779]: INFO [sshd] Found 164.92.114.201 - 2022-05-23 15:16:54
2022-05-23 15:16:55,895 fail2ban.filter [1539779]: INFO [sshd] Found 164.92.114.201 - 2022-05-23 15:16:55
2022-05-23 15:16:59,159 fail2ban.filter [1539779]: INFO [sshd] Found 164.92.114.201 - 2022-05-23 15:16:58
2022-05-23 15:16:59,196 fail2ban.actions [1539779]: WARNING [sshd] 164.92.114.201 already banned
2022-05-23 15:17:02,084 fail2ban.filter [1539779]: INFO [sshd] Found 164.92.114.201 - 2022-05-23 15:17:02
2022-05-23 15:17:03,910 fail2ban.filter [1539779]: INFO [sshd] Found 164.92.114.201 - 2022-05-23 15:17:03
2022-05-23 15:17:08,452 fail2ban.filter [1539779]: INFO [sshd] Found 164.92.114.201 - 2022-05-23 15:17:08
2022-05-23 15:17:11,374 fail2ban.filter [1539779]: INFO [sshd] Found 164.92.114.201 - 2022-05-23 15:17:11
2022-05-23 15:17:14,259 fail2ban.filter [1539779]: INFO [sshd] Found 164.92.114.201 - 2022-05-23 15:17:14
2022-05-23 15:17:14,623 fail2ban.actions [1539779]: WARNING [sshd] 164.92.114.201 already banned
2022-05-23 15:17:16,096 fail2ban.filter [1539779]: INFO [sshd] Found 164.92.114.201 - 2022-05-23 15:17:16
2022-05-23 15:17:19,068 fail2ban.filter [1539779]: INFO [sshd] Found 164.92.114.201 - 2022-05-23 15:17:18
2022-05-23 15:17:20,671 fail2ban.filter [1539779]: INFO [sshd] Found 164.92.114.201 - 2022-05-23 15:17:20
2022-05-23 15:17:24,664 fail2ban.filter [1539779]: INFO [sshd] Found 164.92.114.201 - 2022-05-23 15:17:24
2022-05-23 15:17:26,514 fail2ban.filter [1539779]: INFO [sshd] Found 164.92.114.201 - 2022-05-23 15:17:26
2022-05-23 15:17:26,646 fail2ban.actions [1539779]: WARNING [sshd] 164.92.114.201 already banned
lastb